7.1

CVSS3.1

CVE-2026-23555 - Xenstored DoS by unprivileged domain

Any guest issuing a Xenstore command accessing a node using the (illegal) node path "/local/domain/", will crash xenstored due to a clobbered error indicator in xenstored when verifying the node path. Note that the crash is forced via a failing assert() statement in xenstored. In case xenstored is…

πŸ“… Published: March 23, 2026, 6:57 a.m. πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

7.8

CVSS3.1

CVE-2026-23554 - Use after free of paging structures in EPT

The Intel EPT paging code uses an optimization to defer flushing of any cached EPT state until the p2m lock is dropped, so that multiple modifications done under the same locked region only issue a single flush. Freeing of paging structures however is not deferred until the flushing is done, and c…

πŸ“… Published: March 23, 2026, 6:56 a.m. πŸ”„ Last Modified: April 13, 2026, 2:28 p.m.

5.3

CVSS3.1

CVE-2025-13997 - King Addons for Elementor <= 51.1.49 - Unauthenticated API Keys Disclosure

The King Addons for Elementor – 4,000+ ready Elementor sections, 650+ templates, 70+ FREE widgets for Elementor plugin for WordPress is vulnerable to unauthenticated API key disclosure in all versions up to, and including, 51.1.49 due to the plugin adding the API keys to the HTML source code via re…

πŸ“… Published: March 23, 2026, 6:41 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

6.4

CVSS3.1

CVE-2025-6229 - Sina Extension for Elementor (Slider, Gallery, Form, Modal, Data Table, Tab, Particle, Free Element…

The Sina Extension for Elementor (Header Builder, Footer Builter, Theme Builder, Slider, Gallery, Form, Modal, Data Table Free Elementor Widgets & Elementor Templates) plugin for WordPress is vulnerable to Stored Cross-Site Scripting via the `Fancy Text Widget` And `Countdown Widget` DOM attributes…

πŸ“… Published: March 23, 2026, 6:41 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

4.8

CVSS4.0

CVE-2026-4577 - code-projects Exam Form Submission update_s4.php cross site scripting

A vulnerability was found in code-projects Exam Form Submission 1.0. The affected element is an unknown function of the file /admin/update_s4.php. Performing a manipulation of the argument sname results in cross site scripting. The attack may be initiated remotely. The exploit has been made public …

πŸ“… Published: March 23, 2026, 6:35 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS3.1

CVE-2026-1969 - ThemeREX Addons < 2.38.5 - Unauthenticated Arbitrary File Upload

The trx_addons WordPress plugin before 2.38.5 does not correctly validate file types in one of its AJAX action, allowing unauthenticated users to upload arbitrary file. This is due to an incorrect fix of CVE-2024-13448

πŸ“… Published: March 23, 2026, 6 a.m. πŸ”„ Last Modified: April 15, 2026, 3:05 p.m.

4.8

CVSS4.0

CVE-2026-4576 - code-projects Exam Form Submission update_s5.php cross site scripting

A vulnerability has been found in code-projects Exam Form Submission 1.0. Impacted is an unknown function of the file /admin/update_s5.php. Such manipulation of the argument sname leads to cross site scripting. The attack can be launched remotely. The exploit has been disclosed to the public and ma…

πŸ“… Published: March 23, 2026, 5:36 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

4.8

CVSS4.0

CVE-2026-4575 - code-projects Exam Form Submission update_s2.php cross site scripting

A flaw has been found in code-projects Exam Form Submission 1.0. This issue affects some unknown processing of the file /admin/update_s2.php. This manipulation of the argument sname causes cross site scripting. The attack can be initiated remotely. The exploit has been published and may be used.

πŸ“… Published: March 23, 2026, 5:36 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

5.3

CVSS3.1

CVE-2025-10734 - ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema …

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to Sensitive Information Exposure in all versions up to, and including, 2.2.12 via the syncedData function. This makes it possible for unauthenticated att…

πŸ“… Published: March 23, 2026, 5:29 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.

7.3

CVSS3.1

CVE-2025-10679 - ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema …

The ReviewX – WooCommerce Product Reviews with Multi-Criteria, Reminder Emails, Google Reviews, Schema & More plugin for WordPress is vulnerable to arbitrary method calls in all versions up to, and including, 2.2.12. This is due to insufficient input validation in the bulkTenReviews function that a…

πŸ“… Published: March 23, 2026, 5:29 a.m. πŸ”„ Last Modified: April 24, 2026, 4:32 p.m.
Total resulsts: 349182
Page 975 of 34,919
Β« previous page Β» next page
Filters